CVE-2021-40884: High severity ProjectSend ProjectSend vulnerability
Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Projectsendto a version that resolves this vulnerability.Fixed in r1295
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-40884.
What is the severity of CVE-2021-40884?
The severity of CVE-2021-40884 is high with a score of 8.1.
What is the affected software?
The affected software is Projectsend version r1295.
How does CVE-2021-40884 impact Projectsend?
CVE-2021-40884 allows a user with an uploader role to download and edit all files of users in the application due to not checking authorization in certain functions.
Is there a fix available for CVE-2021-40884?
At the moment, there is no official fix available for CVE-2021-40884. It is recommended to monitor the project's GitHub page for updates.